Access control method, system and equipment based on zero-trust system and medium

By matching user access data with the risk rule library and risk model library of the zero-trust system, multi-grained risk vectors are generated, and vector summing and weighting are performed according to the preset granularity mapping strategy and granularity access order, the problem that a single granularity disposal method in the existing technology cannot adapt to different risk scenarios, and accurate evaluation of risk granularity and fine-grained access control are achieved.

CN120165983AActive Publication Date: 2025-06-17BEIJING TRUSFORT TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510630899.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-06-17
Estimated Expiration
2045-05-16

AI Technical Summary

Technical Problem

In actual application, the existing zero-trust system has a single granularity treatment method that cannot accurately adapt to different risk scenarios. When connected to the artificial intelligence model, the risk score is fuzzy, making it impossible to accurately judge the source of the risk and take corresponding measures.

Method used

By receiving user access requests, obtaining user access data, and matching it with the risk rule library and risk model library of the zero-trust system, a multi-grained risk vector is generated. Then, according to the preset granularity mapping strategy and granularity access order, the risk vector results are vector summed and weighted to generate the final risk vector results for multi-stage linkage access control.

Benefits of technology

Accurate assessment of risk granularity and fine-grained access control are achieved, which can minimize the impact on users' use of business systems while ensuring security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165983A_ABST
    Figure CN120165983A_ABST
Patent Text Reader

Abstract

The invention provides an access control method, system and device based on a zero-trust system and a medium, and relates to the technical field of network information security, and the method comprises the following steps: receiving a user access request, and obtaining user access data of a current user; matching the user access data with a risk rule library and a risk model library of the zero-trust system to obtain a risk rule and / or risk model output triggered by a user; according to a preset granularity mapping strategy, converting the risk rule and / or risk model output triggered by the user into a multi-granularity risk vector; vector summation is carried out on the risk vectors obtained through conversion, a risk vector result is generated, and the risk vector result comprises scores of the user in all the granularities; and according to the risk vector result and the granularity access sequence, executing multi-level linkage access control on the user. Accurate assessment of risk granularity and access control of fine granularity are realized through calculation of each granularity score and multi-level linkage access control in combination with a granularity access sequence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network information security technology, and particularly to an access control method, system, device, and medium based on a zero-trust architecture. Background Art

[0002] In the current field of network security, the zero-trust architecture, as an important security architecture concept, aims to ensure security while minimizing interference with users' access to business systems as much as possible. However, existing zero-trust related products still have obvious deficiencies in practical applications.

[0003] On the one hand, existing zero-trust systems usually adopt a single-granularity handling method. For example, when blocking, they uniformly disconnect the terminal. This single handling method cannot accurately adapt to different risk scenarios and is difficult to minimize the impact on users' access to business systems while ensuring security. On the other hand, when an artificial intelligence model is accessed, the risk scores it feedback often blur the granularity of risk occurrence, resulting in the inability to accurately determine the risk source and take corresponding targeted measures. Therefore, how to provide a technical solution that can accurately evaluate the risk granularity and perform effective access control at the corresponding granularity has become an urgent technical problem to be solved. Summary of the Invention

[0004] This application provides an access control method, system, device, and medium based on a zero-trust architecture to at least solve the above technical problems existing in the prior art.

[0005] According to a first aspect of this application, an access control method based on a zero-trust architecture is provided. The method includes: Receiving a user access request and obtaining the user access data of the current user; Matching the user access data with the risk rule library and risk model library of the zero-trust architecture to obtain the risk rules triggered by the user and / or the output of the risk model; According to a preset granularity mapping strategy, converting the risk rules triggered by the user and / or the output of the risk model into a multi-granularity risk vector; performing vector summation on the converted risk vector to generate a risk vector result, where the risk vector result includes the scores of the user at each granularity; Performing multi-level linked access control on the user according to the risk vector result and the granularity access order.

[0006] In an implementable embodiment, the preset granularity mapping strategy includes: Performing granularity correlation analysis on the risk rules to generate a multi-granularity risk vector corresponding to the risk rules; Converting the output of the risk model into a multi-granularity risk vector corresponding to the risk model.

[0007] In an implementable embodiment, the vector summation of the converted risk vectors includes: Performing a preliminary vector summation on all risk vectors of multiple granularities to obtain an initial risk vector result; Weighting the initial risk vector result according to the granularity weighting vector to obtain a risk vector result; Wherein, the granularity weighting vector includes the weights of each granularity, and the weights are determined based on the granularity levels of each granularity.

[0008] In an implementable embodiment, the multiple granularities include account granularity, terminal granularity, application service granularity, URL granularity, and data field granularity.

[0009] In an implementable embodiment, the granularity access order is account granularity, terminal granularity, application service granularity, URL granularity, and data field granularity; correspondingly, The multi-level linked access control performed on the user according to the risk vector result and the granularity access order includes: In the order of account granularity, terminal granularity, application service granularity, URL granularity, and data field granularity, comparing the cumulative scores of each granularity with a first preset disposal threshold and a second preset disposal threshold step by step according to the risk vector result to obtain the risk level of the corresponding granularity, and performing corresponding access control according to the risk level at the corresponding granularity, where the access control includes release, enhanced authentication, and blocking; Wherein, when blocking is triggered at any granularity, perform the blocking at that granularity and stop subsequent operations.

[0010] In an implementable embodiment, comparing the cumulative scores of each granularity with a first preset disposal threshold and a second preset disposal threshold step by step according to the risk vector result to obtain the risk level of the corresponding granularity, includes: In the case where the cumulative score of each granularity is less than the first preset disposal threshold, determining that the risk level of the user at the current granularity is low risk; In the case where the cumulative score of each granularity is greater than the first preset disposal threshold and less than the second preset disposal threshold, determining that the risk level of the user at the current granularity is medium risk; In the case where the cumulative score of each granularity is greater than the second disposal threshold, determining that the risk level of the user at the current granularity is high risk; Wherein, the cumulative score of each granularity is used to show the total score of the current granularity and all its previous granularities.

[0011] In an implementable embodiment, performing corresponding access control according to the risk level at the corresponding granularity, includes: In the case where the risk level of the corresponding granularity is low risk, performing a release operation; When the risk level at the corresponding granularity is medium risk, perform enhanced authentication operations; When the risk level at the corresponding granularity is high risk, perform blocking operations; Among them, performing a blocking operation at the account granularity includes restricting logging in through the current account; Performing a blocking operation at the terminal granularity includes restricting logging in through the current terminal; Performing a blocking operation at the application service granularity includes restricting access through a specific Internet protocol address or port; Performing a blocking operation at the URL granularity includes restricting access to URL resources; Performing a blocking operation at the data field granularity includes desensitizing the data and only displaying the desensitized data.

[0012] According to the second aspect of the present application, there is provided an access control system based on a zero-trust architecture, the system includes: A controller component, connected to a zero-trust client, for receiving a user access request and obtaining user access data of the current user; A risk assessment module, for matching the user access data with a risk rule library and a risk model library of the zero-trust architecture to obtain risk rules and / or risk model outputs triggered by the user; according to a preset granularity mapping strategy, converting the risk rules and / or risk model outputs triggered by the user into a multi-granularity risk vector; performing vector summation on the converted risk vector to generate a risk vector result, the risk vector result including the scores of the user at each granularity; The controller component is further configured to perform multi-level linked access control on the user according to the risk vector result and the granularity access order.

[0013] According to the third aspect of the present application, there is provided an electronic device, including: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method of the present application.

[0014] According to the fourth aspect of the present application, there is provided a non-transitory computer-readable storage medium storing computer instructions, the computer instructions being used to cause the computer to execute the method of the present application.

[0015] The access control method, system, device and medium based on the zero-trust system of the present application analyze the risk rules and / or risk model outputs triggered by user access to data through a risk rule library and a risk model library, and vectorially transform them into scores in each dimension. Then, combined with the granular access order, multi-level linked access control is performed, realizing accurate evaluation of risk granularity and fine-grained access control.

[0016] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] By referring to the following detailed description with reference to the accompanying drawings, the above and other objects, features and advantages of the exemplary embodiments of the present application will become readily understood. In the drawings, several embodiments of the present application are shown in an exemplary rather than restrictive manner, wherein: In the drawings, the same or corresponding reference numerals represent the same or corresponding parts.

[0018] Figure 1 It shows a schematic implementation flow diagram of the access control method based on the zero-trust system provided by the embodiment of the present application; Figure 2 It shows a schematic implementation flow diagram of the vector summation operation of the access control method based on the zero-trust system provided by the embodiment of the present application; Figure 3 It shows a schematic composition structure diagram of the access control system based on the zero-trust system provided by the embodiment of the present application; Figure 4 It shows a schematic composition structure diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] To make the objectives, features, and advantages of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0020] Figure 1 It shows a schematic implementation flow diagram of the access control method based on the zero-trust system provided by the embodiment of the present application.

[0021] Refer to Figure 1 , the present application provides an access control method based on the zero-trust system, and the method includes: Operation 101: Receive a user access request and obtain the user access data of the current user.

[0022] The zero-trust architecture focuses on the security control of the process where a user accesses business system data through a client, aiming to prevent potential security risks.

[0023] When a user initiates a login through a client, access control is enabled, and the user access data generated during the user access process is obtained in real time, including but not limited to login time, device information, network environment, operation behavior, etc.

[0024] Operation 102: Match the user access data with the risk rule library and risk model library of the zero-trust architecture to obtain the risk rules and / or risk model outputs triggered by the user.

[0025] Based on the historical data accumulated over a long time and rich practical experience of the zero-trust architecture, a complete risk rule library and risk model library have been pre-constructed. The risk rule library covers a variety of known and explicit risk rules, which are assertions or propositions for evaluating whether a user's behavior is risky. For example, a risk rule can be the normal access time of a user, and if the user accesses outside the normal access time, the risk rule is triggered; the risk model library deploys multiple advanced risk models, such as malicious traffic detection models, business behavior analysis models, etc., which are mainly used to identify unknown and potential risk factors.

[0026] Among them, the risk rules in the risk rule library include but are not limited to a user account logging in on multiple devices in a short period, a certain device logging in to multiple accounts in a short period, a business system logging in outside working hours, a user from the Internet accessing a certain port, etc.

[0027] For the real-time obtained user access data, these data are first subjected to necessary preprocessing to organize and adjust the valid information in the user access data to meet the input requirements of risk rules and risk models. Specifically, through preprocessing the user access data, the valid data items in the user access data are aligned with the input formats, data types, etc. requirements of risk rules and risk models. After completion of alignment, risk rules matching the user access data are retrieved from the risk rule library, and according to the input requirements of each model in the risk model library, the aligned data are respectively input into the corresponding risk models to obtain the output results of the risk models. For example, the input requirements of the malicious traffic model are usually all data related to traffic, and the user access data meeting this requirement is input into the malicious traffic model.

[0028] In an embodiment of the present application, the output of the risk model is a quantitative score for potential risks at each granularity during the access process. The risk model is trained based on a conventional neural network architecture and can accurately identify and extract key risk factors during the access process, such as risk behaviors, malicious traffic attacks, malicious operations, etc. Based on the correlation analysis between the risk factors and each granularity of the access process, it outputs the scores of the risk factors at each granularity. Here, the granularity refers to the risk source, such as accounts, terminals, ports, addresses, etc. It should be noted that the risk model in the embodiments of the present application is only triggered for output when a risk factor is identified.

[0029] Operation 103: According to the preset granularity mapping strategy, convert the risk rules and / or the output of the risk model triggered by the user into a multi-granularity risk vector; perform vector summation on the converted risk vector to generate a risk vector result, and the risk vector result includes the scores of the user at each granularity.

[0030] For the zero-trust system, a granularity mapping strategy is preset in advance, and the method of converting risk rules and the output of the risk model into a multi-granularity risk vector is configured in the granularity mapping strategy.

[0031] In an embodiment of the present application, the preset granularity mapping strategy includes: performing granularity correlation analysis on the risk rules to generate a multi-granularity risk vector corresponding to the risk rules; converting the output of the risk model into a multi-granularity risk vector corresponding to the risk model.

[0032] Specifically, for the triggered risk rules, perform granularity correlation analysis on each risk rule, and based on the correlation analysis results with each granularity, output the risk scores for the corresponding granularities, and construct a risk vector based on the risk scores for each granularity. Among them, the correlation analysis can be obtained through methods such as rule semantic matching or feature importance analysis based on machine learning. The manifestation form of the risk vector can be R={F1, F2……Fn}, where F1-Fn represent the risk scores for the 1-nth granularities.

[0033] In an embodiment of the present application, the correlation analysis between the rule and the granularity can be performed through explicit matching based on rule semantics or feature importance analysis based on machine learning. Specifically, for the correlation analysis through the explicit matching method based on rule semantics, it includes: by parsing the text description or structured conditions of the rule, directly matching its association strength with each granularity (such as account level, terminal level, etc.); for the correlation analysis through the feature importance analysis method based on machine learning, it includes: encoding the granularity as a model feature, training a rule trigger prediction model (such as a classifier), and using the feature importance to inversely deduce the association strength between the rule and each granularity. Among them, the association strength can be regarded as the score for each granularity.

[0034] For the output of the risk model, since the risk model directly outputs the scores for each granularity, after obtaining the output of the risk model, the scores of each granularity output by the risk model can be directly converted into a risk vector, and the form of the risk vector is the same as the form shown in the above risk rules.

[0035] After performing vector conversion on the outputs of each risk rule and each risk model, sum all the risk vectors to obtain a risk vector result. Among them, the risk vector result includes the final scores at each granularity.

[0036] Operation 104, perform multi-level linked access control on the user according to the risk vector result and the granularity access order.

[0037] The granularity access order refers to the order in which the user passes through each granularity when accessing the system. For example, if the user first logs in to the terminal using an account and then accesses resources, the granularity access order is account, terminal, resource.

[0038] After determining the risk vector result, perform access control on the user level by level according to the scores of the corresponding granularities in the granularity access order. Among them, the score corresponding to each granularity includes the scores of all previous granularities within that granularity. For example, when the risk vector result is R = {F1, F2... Fn}, the score used for access control at the first granularity is F1, and the score used for access control at the second granularity is F1 + F2, and so on. The multi-level linked access control can be regarded as that only when all previous granularity access controls are determined to be allowed, the access control of the current granularity is then executed.

[0039] In this way, in the embodiment of the present application, by analyzing the risk rules and / or risk model outputs triggered by the user access data through the risk rule library and the risk model library, and vectorially converting them into scores of each granularity, and then performing multi-level linked access control in combination with the granularity access order, accurate evaluation of risk granularity and fine-grained access control are achieved.

[0040] Figure 2 Shows a schematic flow chart of the implementation of the vector summation operation of the access control method based on the zero-trust architecture provided by the embodiment of the present application.

[0041] Refer to Figure 2 , in an embodiment of the present application, performing vector summation on the converted risk vectors includes: Operation 201, perform preliminary vector summation on all multi-granularity risk vectors to obtain an initial risk vector result.

[0042] Since the risk rule and risk model outputs correspond to different risks respectively, therefore, first sum the vectorized results of all risk rules and / or the vectorized results of all risk model outputs to determine all risk scores of each granularity.

[0043] Operation 202 weights the initial risk vector result according to the granularity weighted vector to obtain the risk vector result; wherein, the granularity weighted vector includes the weights of each granularity, and the weights are determined based on the granularity levels of each granularity.

[0044] Similar to the highest privilege and the lowest privilege, there are usually distinctions in the levels of each granularity. For example, for the account granularity, there are privileged accounts and ordinary accounts; for the terminal granularity, there are personal terminals and private terminals; for the interface granularity, there are specific interfaces and ordinary interfaces. Therefore, in order to better implement the deviation correction control for each granularity, before weighting the initial risk vector result, the granularity levels of each granularity are determined according to the attribute data such as users, devices, and networks in the user access data during actual access, and higher granularity levels are given to special attributes. Then, the corresponding weights are dynamically configured for each granularity according to the granularity levels, and the weights of multiple granularities are constructed into a granularity weighted vector.

[0045] After calculating the initial risk vector result, multiply the initial risk vector result by the granularity weighted vector to obtain the final risk vector result.

[0046] In an embodiment of the present application, the multi-granularity during the access process includes at least account granularity, terminal granularity, application service granularity, URL (Uniform Resource Locator) granularity, and data field granularity.

[0047] Specifically, in order to implement fine-grained access control, the present application designs to perform access control from five granularities: account granularity, terminal granularity, application service granularity, URL granularity, and data field granularity. Among them, the account granularity can be understood as being for a certain account; the terminal granularity can be understood as being for a certain terminal; the application service granularity can be understood as being for a specific target business system, service, or host, which is a combination of IP (Internet Protocol) and port; the URL granularity can be understood as a business system based on HTTP (HyperText Transfer Protocol) or HTTPS (HyperText Transfer Protocol Secure), for a specific URL; the data field granularity can be understood as being for specific fields or data displayed on the page, such as ID card numbers, mobile phone numbers, bank card numbers, etc.

[0048] In one embodiment of the present application, according to the risk vector result and the granular access order, a multi-level linkage access control is performed on the user, including: in the order of account granularity, terminal granularity, application service granularity, URL granularity and data field granularity, the cumulative score of each granularity is compared with the first preset disposal threshold and the second preset disposal threshold according to the risk vector result, and the risk level of the corresponding granularity is obtained, and the corresponding access control is performed according to the risk level at the corresponding granularity, and the access control includes release, enhanced authentication and blocking. Wherein, when any granularity triggers blocking, the blocking of the granularity is executed and subsequent operations are stopped.

[0049] According to the analysis of the user access system process, the user access process goes through account granularity, terminal granularity, application service granularity, URL granularity and data field granularity. Therefore, the configuration granularity access order is account granularity, terminal granularity, application service granularity, URL granularity and data field granularity.

[0050] In order to avoid blocking at a single granularity, a handling threshold for the entire access process is configured, which includes a first preset handling threshold and a second preset handling threshold for judging the risk level. At each granularity, the score of its previous granularity is continuously accumulated, and the accumulated score is compared with the handling threshold to obtain the risk level for the current granularity.

[0051] In one embodiment of the present application, when the cumulative score of each granularity is less than the first preset disposal threshold, the risk level of the user at the current granularity is determined to be low risk; when the cumulative score of each granularity is greater than the first preset disposal threshold and less than the second preset disposal threshold, the risk level of the user at the current granularity is determined to be medium risk; when the cumulative score of each granularity is greater than the second disposal threshold, the risk level of the user at the current granularity is determined to be high risk; wherein the cumulative score of each granularity is used to show the sum of the scores of the current granularity and all its predecessor granularities.

[0052] The first preset handling threshold is used to determine whether it is necessary to strengthen authentication. If it is lower than the threshold, it means that it meets the low risk and does not need to strengthen authentication. If it is higher than the threshold, it is determined to be medium risk and needs to strengthen authentication. In order to improve security precautions, a second preset handling threshold is also configured on the basis of the first preset handling threshold. The second preset handling threshold is used to determine whether blocking is required. If it exceeds the second preset handling threshold, it means that there is a high risk and it is directly blocked without strengthening authentication.

[0053] According to the granular access order, release, enhanced authentication and blocking are performed at each granularity based on the comparison between the corresponding cumulative score and the two disposal thresholds.

[0054] Among them, in order to avoid wasting computing resources and improve security prevention, the scoring comparison and access control of the current granularity are only performed when all the previous granularities at the current granularity are not blocked. If there is a block in the previous granularity, the access control operations for all subsequent granularities are default stopped.

[0055] In addition to stopping subsequent operations in case of a block, the subsequent access control operations are also stopped when enhanced authentication occurs at a certain granularity until the granularity where enhanced authentication occurs is determined to pass enhanced authentication and is released.

[0056] In an embodiment of the present application, when the risk level corresponding to the granularity is low risk, a release operation is performed; when the risk level corresponding to the granularity is medium risk, an enhanced authentication operation is performed; when the risk level corresponding to the granularity is high risk, a blocking operation is performed. Among them, the blocking operation at the account granularity includes restricting login through the current account; the blocking operation at the terminal granularity includes restricting login through the current terminal; the blocking operation at the application service granularity includes restricting access through a specific Internet protocol address or port; the blocking operation at the URL granularity includes restricting access to URL resources; the blocking operation at the data field granularity includes desensitizing the data and only displaying the desensitized data.

[0057] For the case of low risk, it can be directly released. For the case of medium risk, enhanced authentication needs to be performed. For the case of high risk, it is directly blocked. Among them, the blocking for the account granularity is to restrict the current account from logging in through any terminal. The blocking for the terminal granularity is to prevent any account from logging in through the current terminal. The blocking for the application service granularity is to restrict access to the business system with a specific IP (Internet protocol address) and port. The blocking for the URL granularity is to restrict access to specific URL resources. The blocking for the data field granularity is to only display the desensitized data and not display important data such as ID numbers and mobile phone numbers.

[0058] In an embodiment of the present application, a blacklist mechanism is also configured for the account granularity and the terminal granularity, that is, once an account and a terminal are determined to be of medium or high risk level, the corresponding account and terminal are added to the disposal list cache. For the accounts in the disposal list, enhanced authentication or blocking is performed for their logins through any terminal. For the terminals in the disposal list, enhanced authentication or blocking is performed for the logins of any account through them. Among them, the account can be cached in the disposal list in the form of an account number, and the terminal can be cached in the disposal list based on its device unique identifier. The device unique identifier of the terminal can be a device fingerprint.

[0059] In an embodiment of the present application, when implementing access control for each granularity, the risk level of each granularity is continuously determined in real time based on user access data. Once it is determined during the access process that the risk level of a certain granularity changes to medium-high risk, the operation is immediately stopped and timely blocking or enhanced authentication is performed at the corresponding granularity. For example, when a user accesses a URL resource, if the current user's account or terminal is determined to be medium-high risk, the user is immediately blocked from accessing the URL resource, and enhanced authentication or blocking is implemented at the account granularity or terminal granularity.

[0060] In an embodiment of the present application, in order to timely remind the user, when blocking or enhancing authentication at each granularity, a reminder of being blocked or undergoing enhanced authentication is also sent to the client to which the user belongs.

[0061] Figure 3 The schematic diagram of the composition structure of the access control system based on the zero-trust architecture provided by the embodiment of the present application is shown.

[0062] Reference Figure 3 To implement the access control method based on the zero-trust architecture of the present application, the present application correspondingly designs a set of access control systems based on the zero-trust architecture, also known as the zero-trust system. This system can be connected to the zero-trust client and the business system to implement access control for users. The system includes a controller component, a forward proxy component, a reverse proxy component, an account credential management and authentication service component, a risk assessment module, and an access control decision-making component.

[0063] Among them, the controller component is connected to the zero-trust client and is used to receive user access requests and obtain the user access data of the current user. Specifically, when a user needs to access the business system, the controller component receives the user access request, performs identity authentication and binding / login, and reports the user access data to the risk assessment module based on the account credential management and authentication service component.

[0064] In addition to uploading the user access data to the risk assessment module, the account credential management and authentication service component also receives attribute data such as the user, device, and network during the current access process, and determines an attribute weighted vector, that is, a granularity weighted vector, based on these special attributes, and then synchronously uploads the granularity weighted vector to the risk assessment module.

[0065] The risk assessment module is used to match the user access data with the risk rule library and risk model library of the zero-trust architecture to obtain the risk rules and / or risk model outputs triggered by the user; according to the preset granularity mapping strategy, convert the risk rules and / or risk model outputs triggered by the user into multi-granularity risk vectors; perform vector summation on the converted risk vectors to generate a risk vector result, and the risk vector result includes the scores of the user at each granularity.

[0066] Among them, the risk assessment module includes an intelligent measurement engine and a rule measurement engine. The intelligent measurement engine is used to obtain the output of the risk model triggered by the user's access to data, and the rule measurement engine is used to obtain the triggered risk rules.

[0067] After the risk assessment module obtains the risk vector result, the risk assessment module transmits the risk vector result to the access control decision-making component. The access control decision-making component determines the access control decision for each granularity and returns the access control decision to the controller component along the original path. The controller component performs multi-level linked access control on the user according to the granularity access order and the corresponding access control decision. Among them, the access control decision is to perform access control such as release, authentication, or block.

[0068] In an embodiment of the present application, the controller component performing multi-level linked access control on the user according to the granularity access order and the corresponding access control decision may include: 1) If the decision includes blocking at the account granularity, access to the logged-in account name is refused. If the decision includes enhanced authentication at the account granularity, the controller component notifies the zero-trust client to pop up a window for enhanced authentication, such as: mobile phone SMS. Once the account granularity risk is triggered, the user will be blocked or required to perform enhanced authentication regardless of which device is used.

[0069] 2) If the decision includes enhanced authentication or blocking at the terminal granularity, the controller component determines the device based on the device fingerprint of the terminal device, and at the same time refuses access to all users bound / logged in on the device, or triggers enhanced authentication.

[0070] 3) If the controller component determines that the user can access the network, the zero-trust client establishes a four-layer network tunnel with the forward proxy component to control the user's access. If, during the user's access to the business system, a block or enhanced authentication at the account granularity or device granularity is triggered, the controller component notifies the forward proxy component to block the user, and the controller component notifies the zero-trust client to pop up a window to notify the customer that they have been blocked or to perform enhanced authentication. If, after the user accesses the forward proxy component, a block or enhanced authentication at the application service granularity is triggered, the controller component notifies the forward proxy component to stop forwarding data to a certain IP and port, and at the same time the controller component notifies the client to pop up a window to inform the user of the block or to request the user to perform enhanced authentication.

[0071] 4) If the user accesses the forward proxy component normally, the access request is forwarded to the reverse proxy component, and the reverse proxy component forwards the request to the business system. If the user request triggers a block or enhanced authentication at the URL granularity, the reverse proxy component inserts a block notification or an enhanced authentication interface into the page returned to the user.

[0072] 5) If enhanced authentication or blocking at the data field granularity is triggered when the user accesses the URL resource, the reverse proxy component matches and desensitizes the data when forwarding the data of the HTTP protocol. If enhanced authentication is required, the reverse proxy component inserts the enhanced authentication page. After authentication, the complete information can be viewed. If blocking is triggered or the enhanced authentication fails, the desensitized data is directly returned.

[0073] In this way, the system of the embodiment of the present application realizes the effective implementation of the method of the present application through the combination of the controller component, the account credential management and authentication service component, the risk assessment module, the access control decision-making component, and the forward / reverse proxy component, improving the accuracy of the risk granularity assessment and the fine-grained access control ability of the system.

[0074] It should be noted that the description of the system of the embodiment of the present application is similar to the description of the above method embodiment, and has similar beneficial effects to the method embodiment, so it will not be elaborated here. For the technical details not covered in the access control system based on the zero-trust architecture provided by the embodiment of the present application, they can be understood according to Figures 1 to 2 the description of any one of the attached drawings.

[0075] According to the embodiment of the present application, the present application also provides an electronic device and a readable storage medium.

[0076] Figure 4 FIG. shows a schematic block diagram of an example electronic device 400 that can be used to implement the embodiments of the present application. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described herein and / or claimed.

[0077] As Figure 4 shown, the device 400 includes a computing unit 401, which can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 402 or the computer program loaded from the storage unit 408 into the random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the device 400 can also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. The input / output (I / O) interface 405 is also connected to the bus 404.

[0078] Multiple components in device 400 are connected to I / O interface 405, including: input unit 406, such as a keyboard, mouse, etc.; output unit 407, such as various types of displays, speakers, etc.; storage unit 408, such as a disk, optical disc, etc.; and communication unit 409, such as a network card, modem, wireless communication transceiver, etc. Communication unit 409 allows device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0079] Computing unit 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of computing unit 401 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 401 executes the various methods and processes described above, such as the access control method based on the zero-trust architecture. For example, in some embodiments, the access control method based on the zero-trust architecture can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 400 via ROM 402 and / or communication unit 409. When the computer program is loaded into RAM 403 and executed by computing unit 401, one or more steps of the access control method based on the zero-trust architecture described above can be executed. Alternatively, in other embodiments, computing unit 401 can be configured to execute the access control method based on the zero-trust architecture in any other suitable manner (e.g., by means of firmware).

[0080] The various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0081] The program code for implementing the method of the present application can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.

[0082] In the context of the present application, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0083] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0084] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0085] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs that run on the respective computers and have a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server that incorporates a blockchain.

[0086] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this application can be achieved, and this is not limited herein.

[0087] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" can explicitly or implicitly include at least one such feature. In the description of this application, "a plurality" means two or more, unless otherwise specifically defined.

[0088] As described above, the above are only specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. An access control method based on a zero-trust system, characterized in that: The method comprises: Receive user access requests and obtain user access data of the current user; Match user access data with the risk rule library and risk model library of the zero trust system to obtain user-triggered risk rules and / or risk model outputs; According to the preset granularity mapping strategy, the risk rules and / or risk model outputs triggered by the user are converted into multi-granularity risk vectors; vector summation is performed on the converted risk vectors to generate a risk vector result, which includes the user's score at each granularity; According to the risk vector results and the granular access order, multi-level linkage access control is performed on the user.

2. The method according to claim 1, characterized in that The preset granularity mapping strategy includes: Perform granular correlation analysis on risk rules to generate multi-granular risk vectors corresponding to the risk rules; The output of the risk model is converted into a multi-granularity risk vector corresponding to the risk model.

3. The method according to claim 1, characterized in that The step of performing vector summation on the risk vector obtained by conversion includes: Perform preliminary vector summation on all multi-granularity risk vectors to obtain the initial risk vector result; Weighting the initial risk vector result according to the granularity weighted vector to obtain a risk vector result; The granularity weighted vector includes the weight of each granularity, and the weight is determined based on the granularity level of each granularity.

4. The method according to claim 1, characterized in that Multiple granularities include account granularity, terminal granularity, application service granularity, URL granularity and data field granularity.

5. The method according to claim 4, characterized in that The granularity access order is account granularity, terminal granularity, application service granularity, URL granularity and data field granularity; accordingly, The performing multi-level linkage access control on the user according to the risk vector result and the granular access order includes: According to the order of account granularity, terminal granularity, application service granularity, URL granularity and data field granularity, the accumulated score of each granularity is compared with the first preset handling threshold and the second preset handling threshold according to the risk vector result, so as to obtain the risk level of the corresponding granularity, and perform corresponding access control according to the risk level at the corresponding granularity, wherein the access control includes release, enhanced authentication and blocking; When blocking is triggered at any granularity, blocking of the granularity is executed and subsequent operations are stopped.

6. The method according to claim 5, characterized in that According to the risk vector result, the cumulative score of each granularity is compared with the first preset treatment threshold and the second preset treatment threshold step by step to obtain the risk level of the corresponding granularity, including: When the accumulated scores of each granularity are less than the first preset handling threshold, determining that the risk level of the user at the current granularity is low risk; When the accumulated scores of each granularity are greater than the first preset handling threshold and less than the second preset handling threshold, it is determined that the risk level of the user at the current granularity is medium risk; When the accumulated scores of each granularity are greater than the second handling threshold, the risk level of the user at the current granularity is judged to be high risk; The cumulative score of each granularity is used to show the sum of the scores of the current granularity and all its predecessor granularities.

7. The method according to claim 6, characterized in that Perform corresponding access control at the corresponding granularity according to the risk level, including: When the risk level of the corresponding granularity is low risk, the release operation is performed; When the risk level of the corresponding granularity is medium risk, the enhanced authentication operation is performed; When the risk level of the corresponding granularity is high risk, a blocking operation is performed; Among them, blocking operations at the account granularity include restricting login through the current account; Blocking operations at the terminal granularity include restricting logins through the current terminal; Blocking operations at the application service granularity include restricting access through specific Internet Protocol addresses or ports; Blocking operations at the URL granularity include restricting access to URL resources; Blocking operations at the data field granularity include desensitizing the data and displaying only the desensitized data.

8. An access control system based on a zero-trust system, characterized in that: The system comprises: A controller component is connected to a zero-trust client to receive user access requests and obtain user access data of the current user; The risk assessment module is used to match the user access data with the risk rule library and risk model library of the zero trust system to obtain the risk rules and / or risk model outputs triggered by the user; according to the preset granularity mapping strategy, the risk rules and / or risk model outputs triggered by the user are converted into multi-granularity risk vectors; vector summing is performed on the converted risk vectors to generate risk vector results, which include the user's score at each granularity; The controller component is also used to perform multi-level linkage access control on the user according to the risk vector result and the granular access order.

9. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to make a computer execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data security grading dynamic access control method based on zero trust model

    CN112235298A

  • Construction method of zero-trust network

    CN113507463A

  • Trust evaluation method and device in zero-trust architecture and electronic equipment

    CN116319026A

  • Zero-trust security access control method

    CN117436097A

  • Dynamic access control method and device fusing industrial situation and zero trust

    CN118573419A